Datastage On Cloud Pak Data IBM Datastage On Cloud Pak Data

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Datastage On Cloud Pak Data.

By the Year

In 2026 there have been 50 vulnerabilities in IBM Datastage On Cloud Pak Data with an average score of 8.5 out of ten.

Year Vulnerabilities Average Score
2026 50 8.47

It may take a day or so for new Datastage On Cloud Pak Data vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Datastage On Cloud Pak Data Security Vulnerabilities

IBM DataStage 5.4.0.0 Path Traversal in Archive Extraction (CVE-2026-84421)
CVE-2026-84421 8.8 - High - September 29, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.

Directory traversal

IBM DataStage on Cloud Pak 5.4.0.0 Directory Traversal via Pathname
CVE-2026-82094 7.1 - High - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.

Directory traversal

IBM DataStage 5.4.0.0 - Unsafe Deserialization Enables Remote Code Execution
CVE-2026-82093 8.8 - High - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

Marshaling, Unmarshaling

IBM DataStage Cloud Pak 5.4.0.0 Remote Auth Cmd Exec via Env Vars
CVE-2026-81552 8.8 - High - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.

Shell injection

IBM DataStage 5.4.0.0 Remote Authenticated ID via X-Forwarded-Proto
CVE-2026-81549 9.6 - Critical - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.

SSRF

IBM DataStage 5.4.0.0 Remote Auth Cmd Exec via OS Cmd Injection
CVE-2026-81548 8.8 - High - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage 5.4.0.0 Remote Authenticated Cmd Exec via Path Traversal
CVE-2026-81547 8.8 - High - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.

Directory traversal

IBM DataStage CPK 5.4.0.0 OS Command Exec via Improper Sanit
CVE-2026-81545 8.8 - High - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage CSP 5.4 RCE via OS command injection
CVE-2026-81539 8.8 - High - September 24, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage on Cloud Pak for Data 5.4.0.0 OS CI RCE
CVE-2026-81537 8.8 - High - September 23, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

Shell injection

IBM DataStage on Cloud Pak for Data 5.4.0.0 XXE Remote Att Info Disclosure
CVE-2026-81536 7.7 - High - September 23, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

XXE

IBM DataStage Cloud Pak 5.4.0.0 Improper Credential Handling (CVE-2026-81208)
CVE-2026-81208 7.7 - High - September 23, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.

Insufficiently Protected Credentials

Remote Auth Secret Leak via File Mounts in IBM DataStage 5.4.0
CVE-2026-80423 8.8 - High - September 23, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

Information Disclosure

IBM DataStage 5.4.0.0 Remote Auth Cmd Exec via OS Cmd Injection
CVE-2026-80425 8.8 - High - September 23, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage Cloud Pak for Data 5.4.0.0 RCE via Connector Prop Escaping
CVE-2026-80412 8.8 - High - September 23, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.

Shell injection

IBM DataStage on Cloud Pak 5.4.0.0 Remote Auth Cmd Exec via OS Injection
CVE-2026-80379 8.8 - High - September 23, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

Command Injection in IBM DataStage 5.4.0.0 via Unescaped OS Command Elements
CVE-2026-17102 8.8 - High - September 22, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage Cloud Pak 5.4.0.0 OS Command Injection (RCE)
CVE-2026-16672 8.8 - High - September 22, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage Cloud Pak 5.4.0.0 px-runtime Remote Auth Cmd Exec
CVE-2026-16469 8.8 - High - September 22, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage 5.4.0.0 OS Command Injection via Authenticated Remote Exec
CVE-2026-16468 8.8 - High - September 22, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection.

Shell injection

OS Command Injection (CVE-2026-16346) DataStage 5.4.0.0 on Cloud Pak
CVE-2026-16346 9.9 - Critical - September 22, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

AuthZ

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could
CVE-2026-16335 8.1 - High - September 14, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

Directory traversal

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could
CVE-2026-16338 9.9 - Critical - September 14, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

External Control of File Name or Path

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could
CVE-2026-16432 7.7 - High - September 14, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

XXE

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could
CVE-2026-16428 8.8 - High - September 14, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

Code Injection

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could
CVE-2026-16466 8.8 - High - September 14, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

Shell injection

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could
CVE-2026-16673 8.8 - High - September 14, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

Shell injection

IBM DataStage on Cloud Pak for Data 5.4.0.0 Auth Bypass Causing DOS
CVE-2026-80378 8.5 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

AuthZ

IBM DataStage on Cloud Pak for Data 5.4.0.0: CSRF Enables Unauthorized Actions
CVE-2026-80380 7.1 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

Session Riding

IBM DataStage Cloud Pak 5.4.0.0 IDOR Causing Runtime Cache Manipulation & DoS
CVE-2026-80434 7.4 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.

Insecure Direct Object Reference / IDOR

IBM DataStage CloudPak Path Traversal 5.4.0.0 Enables Auth Remote File Write
CVE-2026-80424 9.1 - Critical - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

Directory traversal

IBM DataStage Cloud Pak 5.4: Authenticated DOS via RabbitMQ Deletion
CVE-2026-80436 8.5 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

AuthZ

IBM DataStage CP4D 5.4.0.0 ds-canvas: Auth. tenant controls outbound fetch URLs
CVE-2026-81207 8.5 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant with no project membership or role fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).

SSRF

IBM DataStage Cloud Pak 5.4 IDOR & Path Traversal via Log Files
CVE-2026-81210 7.7 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data row samples. This is the operator's tenant-to-tenant PVC-leakage threat verbatim; MEDIUMHIGH via threat match.

Insecure Direct Object Reference / IDOR

IBM DataStage 5.4.0.0 Path Traversal Enables Auth Tenant Ruleset Overwrite
CVE-2026-81540 8.5 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

Directory traversal

IBM DataStage 5.4.0.0 RCE via improper OS command escaping
CVE-2026-81550 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage Cloud Pak 5.4.0 Path Traversal Enables Remote File Write
CVE-2026-81551 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

Directory traversal

IBM DataStage on Cloud Pak for Data 5.4.0.0 Path Traversal Remote Auth Attack
CVE-2026-81554 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

Directory traversal

IBM DataStage 5.4.0.0 APT: Absolute-Path Traversal Remote Auth Get Sensitive Info
CVE-2026-82092 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

Absolute Path Traversal

IBM DataStage Cloud Pak 5.4.0.0 OS Command Injection via Improper Escaping
CVE-2026-82095 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage on Cloud Pak for Data 5.4.0.0 SSRF RCE
CVE-2026-82097 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

SSRF

Remote Authenticated Command Injection in IBM DataStage Cloud Pak 5.4.0.0
CVE-2026-82098 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage on Cloud Pak 5.4.0.0: Authenticated RCE via OS Command Injection
CVE-2026-82099 8.8 - High - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Shell injection

IBM DataStage 5.4.0.0 Path Traversal DoS (Auth)
CVE-2026-82100 9.6 - Critical - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

Directory traversal

IBM DS Cloud Pak 5.4 Improper Auth Bypass Remote Data Exfil
CVE-2026-82107 9.6 - Critical - September 10, 2026

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

authentification

IBM DataStage 5.1.2-5.3.0 Auth Cmd Exec via Job Subroutine
CVE-2025-13686 6.3 - Medium - March 03, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the job subroutine component.

Shell injection

IBM DataStage on Cloud Pak for Data 5.1.2-5.3.0 UDF RCE via input validation
CVE-2025-13687 6.3 - Medium - March 03, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the user-defined function component.

Shell injection

IBM DataStage CloudPak 5.1.2-5.3.0 Cmd Injection via Wrapped Cmd Comp
CVE-2025-13688 6.3 - Medium - March 03, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the wrapped command component.

Shell injection

IBM DataStage on Cloud Pak for Data 5.1.2-5.3.0 - HTTP Resp Sensitive Disclosure
CVE-2025-13616 6.5 - Medium - March 03, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.

Exposure of Sensitive System Information to an Unauthorized Control Sphere

IBM DataStage Cloud Pak 5.1.25.3.0 Sensitive Data in HTTP Response
CVE-2025-13691 8.1 - High - February 17, 2026

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Datastage On Cloud Pak Data or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe